CVE-2020-2226
published 2020-07-15CVE-2020-2226: Jenkins Matrix Authorization Strategy Plugin 2.6.1 and earlier does not escape user names shown in the configuration, resulting in a stored cross-site…
PriorityP424medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.92%
56.1th percentile
Jenkins Matrix Authorization Strategy Plugin 2.6.1 and earlier does not escape user names shown in the configuration, resulting in a stored cross-site scripting vulnerability.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | deployer_framework_plugin | — | — |
| jenkins | gitlab_authentication_plugin | — | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | jenkins_weekly | — | — |
| jenkins | matrix_authorization_strategy | <= 2.6.1 | — |
| jenkins | matrix_authorization_strategy_plugin | — | — |
| jenkins | matrix_project_plugin | — | — |
| jenkins_project | jenkins_matrix_authorization_strategy_plugin | unspecified – 2.6.1 | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Stored XSS vulnerability in Jenkins Matrix Authorization Strategy Plugin
ghsa·2022-05-24
CVE-2020-2226 [HIGH] CWE-79 Stored XSS vulnerability in Jenkins Matrix Authorization Strategy Plugin
Stored XSS vulnerability in Jenkins Matrix Authorization Strategy Plugin
Matrix Authorization Strategy Plugin 2.6.1 and earlier does not escape user names shown in the permission table. This results in a stored cross-site scripting (XSS) vulnerability. When using project-based matrix authorization, this vulnerability can be exploited by a user with Job/Configure or Agent/Configure permission, otherwise by users with Overall/Administer permission.
Matrix Authorization Strategy Plugin 2.6.2 escapes user names in the permission table.
OSV
Stored XSS vulnerability in Jenkins Matrix Authorization Strategy Plugin
osv·2022-05-24
CVE-2020-2226 [HIGH] Stored XSS vulnerability in Jenkins Matrix Authorization Strategy Plugin
Stored XSS vulnerability in Jenkins Matrix Authorization Strategy Plugin
Matrix Authorization Strategy Plugin 2.6.1 and earlier does not escape user names shown in the permission table. This results in a stored cross-site scripting (XSS) vulnerability. When using project-based matrix authorization, this vulnerability can be exploited by a user with Job/Configure or Agent/Configure permission, otherwise by users with Overall/Administer permission.
Matrix Authorization Strategy Plugin 2.6.2 escapes user names in the permission table.
Jenkins
Jenkins Security Advisory 2020-07-15
vendor_jenkins·2020-07-15·CVSS 5.4
CVE-2020-2220 [MEDIUM] Jenkins Security Advisory 2020-07-15
Title: Jenkins Security Advisory 2020-07-15
Jenkins Security Advisory 2020-07-15
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Jenkins (core)
Deployer Framework
Plugin
GitLab Authentication
Plugin
Matrix Authorization Strategy
Plugin
Matrix Project
Plugin
Descriptions
Stored XSS vulnerability in jo
Red Hat
jenkins-2-plugins/matrix-auth: Stored XSS vulnerability in Matrix Authorization Strategy Plugin
vendor_redhat·2020-07-15·CVSS 5.4
CVE-2020-2226 [MEDIUM] CWE-79 jenkins-2-plugins/matrix-auth: Stored XSS vulnerability in Matrix Authorization Strategy Plugin
jenkins-2-plugins/matrix-auth: Stored XSS vulnerability in Matrix Authorization Strategy Plugin
Jenkins Matrix Authorization Strategy Plugin 2.6.1 and earlier does not escape user names shown in the configuration, resulting in a stored cross-site scripting vulnerability.
A flaw was found in the Matrix Authorization Strategy Plugin version 2.6.1 and prior. User names are not escaped in the permission table which could lead to a stored cross-site scripting (XSS) vulnerability. The user must have the Agent/Configure, Job/Configure, or Overall/Administer permissions for this exploit to function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
No detection rules found.
No public exploits indexed.
2020-07-15
Published